Watch out for the ClickFix Phishing Scheme

A potent new social-engineering technique that tricks users into pasting malicious commands.

Back to all articles
Watch out for the ClickFix Phishing Scheme
February 23, 20266 minPhishing

ClickFix prompts users to "verify" themselves by pasting a one-line PowerShell command. The result: instant remote-access trojan. Train staff to never paste anything from a captcha. Your EDR should also block unsigned PowerShell from the user temp directory.

Need help putting this into practice?

Schedule a 15-minute consultation with our team.

Schedule a call